The small, documented codebase and clear licensing make its behavior easy to inspect. There is little evidence of ongoing security or maintenance oversight, so future fixes may depend on one maintainer.
68%
Total Score
50
88
83
One registry maintainer is listed, limiting publishing redundancy. The repository is user-owned, so this is a modest resilience concern rather than evidence of abandonment by itself.
The package has seven releases over roughly 12 years, but none in the last 12 months and a median release interval of about 484 days. This suggests a mature but slow-moving project rather than active maintenance.
The repository had zero commits and zero active maintainers during the last three months. Combined with the last push in September 2024, this indicates maintenance has largely stalled.
There are no open issues and only one open pull request, with no issue or pull-request activity in the past month. This is consistent with a small, quiet project but provides little evidence of active support.
Composer build tooling is present, but no security scanning tool is configured. For this small package that is a transparency and upkeep gap, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.